vulnerability

Stories From An IT Security Professional

vulnerability.ch now HSTS preloaded

As of September 8th, 2015 this website has been added to the HSTS preloading list of Google Chrome. I expect Firefox to follow soon. This ensures that all connections from your browser is sent over encrypted HTTP, even when you  try to connect with http://vulnerability.ch. You can check HSTS-Settings in Chrome under: chrome://net-internals/#hsts How to add […]

Continue Reading

Google’s BeyondCorp and some Thoughts

One of the big news stories last week was the Wall Street Journal article, reporting that Google has “given up on their internal network” and are moving their business applications to the internet (called BeyondCorp). The reason behind is that they don’t see the internal network as private/protectable anymore. With todays adversaries, malware and general lack […]

Continue Reading

Hack of the Day: Xing

Hack of the Day – Xing I have been using Xing for close to eight years. And I have tried the Premium feature for a little while. But luckily my card run out and that solved the hassle ton cancel my account 😉 However, have you every seen this on your front page: The “Profile Visitors” […]

Continue Reading

Creative Commons: Donors Data Leak

A few days ago has the Creative Commons team sent out an email, informing me and some other donors about a data leak that happened on their GitHub repository: Creative Commons believes in open, frank, and prompt communication with our community, including our donors. We also take your privacy seriously. We are committed to responsibly guarding the personal information you […]

Continue Reading

Zeitgeist Daemon on Xubuntu does not respect your privacy

I toyed around with my Xubuntu, and found the strange named process “Zeitgeist”. What’s this? “zeitgeist-daemon  is  a  daemon which keeps track of activities on your system (file usage, browser history, calendar events, etc.) and  logs them  into  a  central  database. It does not only create a chronologic register, but also supports tagging  and  can […]

Continue Reading